14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

squid-ldap-match<br />

http://marasystems.com/download/LDAP_Group/<br />

Squid also supports external ACL helpers, which are programs designed to<br />

communictate via standard in and standard out with the squid daemon.<br />

One such helper is squid-ldap-match, which enables an ACL to perform a<br />

lookup in the DSA for a user's group membership. Via this mechanism<br />

access via squid can be controlled through standard group memberships<br />

making administration simple.<br />

external_acl_type ldap_group concurrency=10 %LOGIN /usr/lib/squid/squid_ldap_match -b<br />

"o=Morrison Industries,c=US" -f "(&(objectclass=posixGroup)(memberuid=%u)(cn=%g))"<br />

-s sub -P -h littleboy -S<br />

acl ldap_internet external ldap_group internet<br />

. . .<br />

http_access allow ldap_internet<br />

. . .<br />

ACL is created.<br />

At this point in the ACL stack any request by<br />

anyone in the group internet is approved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!